Self-hosting
Updated
The management dashboard and the four product APIs. Images come from the
private registry named in your registry-access email
(<registry-host>/docker/kryptic/<name>:<tag>). Docs, the public site,
Public API, and Internal API are not in this stack.
Self-hosting requires a Business or Enterprise licence key. There is no free self-hosted tier. If you are still evaluating, try Kryptic on a cloud plan first.
Your registry-access email has:
| Field | Where you put it |
|---|---|
| Registry host | docker login, --docker-server, and DOCKER_REGISTRY (<host>/docker) |
| Helm repo URL | helm repo add kryptic <url> |
| Username + the password you set | docker login or helm repo add, and the image pull secret |
| Image tag | KRYPTIC_VERSION in .env or Helm values |
| Helm chart version | helm install --version |
| Air-gap bundle link | docker load on offline hosts, see Air-gapped |
The attached kryptic-selfhost.zip has Compose, .env.example, up.sh,
values.example.yaml, and the Helm chart (kryptic-helm-<version>.tgz). The
same email links the air-gap image tarball, downloadable with your
registry credentials. See Air-gapped.
Pick an install path:
Keys, URLs, Postgres, and upgrades are in Settings and options.
Create your organization
After the stack is up, open the dashboard and register the first organization. There is no confirmation email. Then initialize encryption under Settings → Encryption before anyone stores secrets. Invite your team. Point developer daemons at your deployment:
kryptic config set-api https://daemon.kryptic.example.com
kryptic login
KRYPTIC_API overrides the saved URL without writing it. Changing the
saved URL signs you out, because tokens belong to one server.
CI runners use KRYPTIC_PIPELINES_API with
kryptic ci export.